Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 220

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Netflix CEO Sarandos visited White House right before streamer said WBD deal is off
World's largest sovereign wealth fund's bets on Big Tech and banking drive gains
U.S. and Iran wrap up 'most intense' nuclear talks with no deal — more negotiations ahead
Target to remove synthetic color from cereals by May end
Jim Cramer's top 10 things to watch in the stock market Friday
Anthropic faces lose-lose scenario in Pentagon conflict as deadline for policy change looms
Special Event: MetaFilter Board Town Hall
How high can oil and gas prices go because of the Iran war? Here are the scenarios
Frieren: Beyond Journey's End: A Demon-Slaying Request
Book: finnegans wake